[go: up one dir, main page]

CN115208690A - Screening processing system based on data classification and classification - Google Patents

Screening processing system based on data classification and classification Download PDF

Info

Publication number
CN115208690A
CN115208690A CN202210951646.2A CN202210951646A CN115208690A CN 115208690 A CN115208690 A CN 115208690A CN 202210951646 A CN202210951646 A CN 202210951646A CN 115208690 A CN115208690 A CN 115208690A
Authority
CN
China
Prior art keywords
data
unit
module
virus
classification
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202210951646.2A
Other languages
Chinese (zh)
Inventor
解培
陈凯
阮安邦
魏明
陈智
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Octa Innovations Information Technology Co Ltd
China Everbright Bank Co Ltd
Original Assignee
Beijing Octa Innovations Information Technology Co Ltd
China Everbright Bank Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Octa Innovations Information Technology Co Ltd, China Everbright Bank Co Ltd filed Critical Beijing Octa Innovations Information Technology Co Ltd
Priority to CN202210951646.2A priority Critical patent/CN115208690A/en
Publication of CN115208690A publication Critical patent/CN115208690A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a screening processing system based on data classification and grading, which can screen received data firstly through the matching of a data receiving module, a data screening module, a control module, a data classification module, a data grading module, a virus killing module and a data storage module, when a virus identification unit identifies that the received data does not contain viruses, the data is controlled to be transmitted to a data identification unit through an MCU (micro control unit) for data identification, and the identified data can be protected through a firewall unit, so that the safety of the received data is improved, when the virus identification unit identifies that the received data contains viruses, the data is controlled to be transmitted to the virus killing module through the MCU for virus killing operation, the identification and virus killing capabilities of the received data viruses are improved, the probability of system disqualification is reduced to a certain extent, and a certain data processing rate is improved.

Description

Screening processing system based on data classification and classification
Technical Field
The invention belongs to the technical field of big data processing, and particularly relates to a screening processing system based on data classification and classification.
Background
Data refers to any record of information electronically or otherwise; the data classification refers to a process of distinguishing and classifying the organization data according to certain principles and methods according to the attributes or characteristics of the organization data, and establishing a certain classification system and arrangement order so as to better manage and use the organization data. The data classification is a process of distinguishing the rework performance and the sensitivity difference of data by adopting a standard and clear method on the basis of data classification and grading the data according to a certain classification principle so as to provide support for the establishment of open and shared security strategies for organizing the data. However, in the current screening process of data classification and classification, the identification power of viruses carried by the received data is low, and when the data carrying the viruses is received and processed, the system can be crashed, so that the data processing speed is affected.
Disclosure of Invention
The invention aims to provide a screening processing system based on data classification and grading, which can screen received data through the cooperation of a data receiving module, a data screening module, a control module, a data classification module, a data grading module, a virus killing module and a data storage module, and when a virus identification unit identifies that the received data contains viruses, the MCU controls the data to be transmitted to the virus killing module for virus killing operation, so that the identification and virus killing capabilities of the received data viruses are improved, and the problems in the background technology are solved.
In order to achieve the purpose, the invention adopts the following technical scheme:
the utility model provides a screening processing system based on data classification is hierarchical, includes data receiving module, data screening module, control module, data classification module, virus antivirus module and data storage module, data receiving module and data screening module electric connection, the data screening module includes data identification unit, virus identification unit and prevents hot wall unit, virus identification unit and data identification unit electric connection, data identification unit and prevent hot wall unit electric connection, the virus identification unit includes the hawk eye engine, control module respectively with data classification module and virus antivirus module electric connection, virus identification unit and virus antivirus unit electric connection, the virus identification unit includes network data package analyzer, data classification module and data classification module electric connection, data classification module and data storage module electric connection.
Preferably, the data receiving module comprises a batch data collector, an embedded operating system is installed in the batch data collector, and the batch data collector is connected with the data screening module through a serial data line.
Preferably, the virus killing module kills viruses screened by the data screening module by a caspasky antivirus program, and the caspasky antivirus program is compatible with a windows system.
Preferably, the control module comprises an MCU, the MCU is used to control the data passing through the virus identification unit to be transmitted to the data identification unit or the virus killing module, when the virus identification unit identifies that the received data does not contain virus, the MCU controls the data to be transmitted to the data identification unit for data identification, and when the virus identification unit identifies that the received data contains virus, the MCU controls the data to be transmitted to the virus killing module for virus killing operation.
Preferably, the data identification unit includes character identification, pattern identification and audio identification, and is configured to identify whether the data belongs to character data, pattern data or audio data, and classify the data according to the identified data type.
Preferably, the firewall unit actively monitors, identifies, alarms, and blocks external data attacks bypassing network boundary protection, data stealing, destruction and damage from internal high-authority users in real time by adopting an active defense technology, provides an active security defense measure from the technical level of database SQL statement fine control, and helps users to deal with data security threats from the inside and the outside by combining with security access control rules independent of a database.
Preferably, the eagle eye engine adopts a machine learning algorithm to solve the safety problem by a mathematical method, the processing capacity of a large number of samples is improved, and all mainstream viruses are searched and killed by the eagle eye engine.
Preferably, the data classification module comprises a text data unit, a graphic data unit and an audio data unit, wherein the text data unit, the graphic data unit and the audio data unit are respectively electrically connected with the control unit and the data classification module, the text data unit is used for classifying received digital data, the graphic data unit is used for classifying the received graphic data, and the audio data unit is used for classifying the received audio data.
Preferably, the data grading module includes a common data unit, an uncommon data unit and a common data unit, and the text data unit, the graphic data unit and the audio data unit correspond to a group of the common data unit, the uncommon data unit and the common data unit.
Preferably, the data storage module includes a main memory and an auxiliary memory, both of which are configured as ROM chips, and both of which are electrically connected to the data classification module.
Compared with the prior art, the screening processing system based on data classification and classification provided by the invention has the following advantages:
according to the invention, through the cooperation of the data receiving module, the data screening module, the control module, the data classification module, the data grading module, the virus killing module and the data storage module, the received data can be screened firstly, when the virus identification unit identifies that the received data does not contain viruses, the MCU is used for controlling the data to be transmitted to the data identification unit for data identification, and the identified data can be protected through the firewall unit, so that the safety of the received data is improved, when the virus identification unit identifies that the received data contains viruses, the MCU is used for controlling the data to be transmitted to the virus killing module for virus killing operation, so that the virus identification and killing capability of the received data is improved, the probability of system disc collapse is reduced to a certain extent, and a certain data processing rate is improved.
Drawings
FIG. 1 is a block diagram of the system of the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. The specific embodiments described herein are merely illustrative of the invention and do not delimit the invention. All other embodiments, which can be obtained by a person skilled in the art without making any creative effort based on the embodiments in the present invention, belong to the protection scope of the present invention.
The invention provides a screening processing system based on data classification and grading, which comprises a data receiving module, a data screening module, a control module, a data classification module, a data grading module, a virus killing module and a data storage module, wherein the data receiving module is electrically connected with the data screening module;
the network packet analyzer is capable of detecting and analyzing security threats while also tracking network devices and uptime. A significant feature of network packet analyzers is to monitor virus and attack signatures and quickly isolate infected systems. Network packet analyzers work in conjunction with IDS, firewall, and Anti-Virus (Anti-Virus) systems-typical network packet analyzers can capture all packets, decode a variety of different protocols, and provide a human-readable result format. Most more sophisticated analyzers also include some statistical reporting functionality. By looking at network traffic, knowing bandwidth utilization and receiving connection dynamics, etc., an administrator can easily determine the work site causing the failure and its cause. The network packet analyzer may be used as an aid to disinfection and IDS systems.
The data receiving module comprises a batch processing data collector, an embedded operating system is arranged in the batch processing data collector, the batch processing data collector is connected with the data screening module through a serial port data line, and the data collector is an automatic device with the functions of field real-time data collection and processing. Generally, the batch processing data acquisition device has the functions of real-time acquisition, automatic storage, real-time display, real-time feedback, automatic processing, automatic transmission and the like, guarantees the authenticity, effectiveness, real-time performance and usability of field data, and can support off-line work.
The virus killing module kills viruses screened out by the data screening module through a caspasky antivirus program, the caspasky antivirus program is compatible with a windows system, the caspasky antivirus program is antivirus software from Russia, and the antivirus software can protect a home user, a workstation, a mail system, a file server and a gateway; in addition, centralized management tools, anti-spam systems, personal firewalls, and protection of mobile devices, including Palm operating systems, laptops, and smart phones, are provided.
The control module comprises an MCU (microprogrammed control unit), the MCU is used for controlling data passing through the virus identification unit to be transmitted to the data identification unit or the virus disinfection module, when the virus identification unit identifies that the received data do not contain viruses, the MCU is used for controlling the data to be transmitted to the data identification unit for data identification, and when the virus identification unit identifies that the received data contain viruses, the MCU is used for controlling the data to be transmitted to the virus disinfection module for disinfection operation.
The data identification unit comprises character identification, graph identification and audio identification and is used for identifying whether the data belongs to character data, graph data or audio data and classifying the data according to the identified data types.
The firewall unit actively monitors, identifies and alarms in real time by adopting an active defense technology, blocks external data attacks bypassing network boundary protection, data stealing, damage and damage of internal high-authority users, provides an active security defense measure from the technical level of database SQL statement fine control, and helps users to deal with data security threats from the inside and the outside by combining with security access control rules independent of a database.
The eagle eye engine adopts a machine learning algorithm to solve the safety problem by a mathematical method, improves the processing capacity of mass samples, and is used for searching and killing all mainstream viruses, the eagle eye engine is a housekeeper second generation antivirus engine, and has the following advantages in terms of performance: the resource occupation is less, the running speed is high, and the operation is lighter; the machine learning algorithm is more intelligent, the virus identification rate is higher, the virus identification speed is increased by 10 percent, and the speed is higher.
The data classification module comprises a text data unit, a graphic data unit and an audio data unit, wherein the text data unit, the graphic data unit and the audio data unit are respectively electrically connected with the control unit and the data classification module, the text data unit is used for classifying received digital data, the graphic data unit is used for classifying the received graphic data, and the audio data unit is used for classifying the received audio data.
The data grading module comprises a common data unit, an uncommon data unit and a common data unit, and the text data unit, the graphic data unit and the audio data unit correspond to a group of common data unit, an uncommon data unit and a common data unit.
The data storage module comprises a main memory and an auxiliary memory, wherein the main memory and the auxiliary memory are both set to be ROM chips and are electrically connected with the data classification module, the main memory and the auxiliary memory are used for storing classified data, the auxiliary memory can be used for backup, and when the data stored on the main memory is lost, the data stored on the auxiliary memory can be retrieved.
Finally, it should be noted that: although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still make modifications to the technical solutions described in the foregoing embodiments, or make equivalent substitutions and improvements to part of the technical features of the foregoing embodiments, and any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims (10)

1. The utility model provides a screening processing system based on data classification is hierarchical, includes data receiving module, data screening module, control module, data classification module, virus killing module and data storage module, its characterized in that: the data receiving module is electrically connected with the data screening module, the data screening module comprises a data identification unit, a virus identification unit and a firewall unit, the virus identification unit is electrically connected with the data identification unit, the data identification unit is electrically connected with the firewall unit, the virus identification unit comprises an eagle eye engine, the control module is respectively electrically connected with the data classification module and the virus antivirus module, the virus identification unit is electrically connected with the virus antivirus unit, the virus identification unit comprises a network data packet analyzer, the data classification module is electrically connected with the data classification module, and the data classification module is electrically connected with the data storage module.
2. The data classification-based ranking screening process system of claim 1 wherein: the data receiving module comprises a batch processing data acquisition unit, an embedded operating system is arranged in the batch processing data acquisition unit, and the batch processing data acquisition unit is connected with the data screening module through a serial port data line.
3. The data classification-based ranking screening process system of claim 1 wherein: the virus disinfection module disinfects viruses screened out by the data screening module through a caspasky disinfection program, and the caspasky disinfection program is compatible with a windows system.
4. The data classification-based ranking screening process system of claim 1 wherein: the control module comprises an MCU (microprogrammed control unit), the MCU is used for controlling data passing through the virus identification unit to be transmitted to the data identification unit or the virus disinfection module, when the virus identification unit identifies that the received data do not contain viruses, the MCU is used for controlling the data to be transmitted to the data identification unit for data identification, and when the virus identification unit identifies that the received data contain viruses, the MCU is used for controlling the data to be transmitted to the virus disinfection module for virus disinfection operation.
5. The data classification ranking-based screening process system of claim 1, wherein: the data identification unit comprises character identification, graph identification and audio identification and is used for identifying whether the data belongs to character data, graph data or audio data and classifying the data according to the identified data types.
6. The data classification ranking-based screening process system of claim 5, wherein: the firewall unit actively monitors, identifies, alarms and blocks external data attacks bypassing network boundary protection, data stealing, destruction and damage of internal high-authority users by adopting an active defense technology in real time, provides an active security defense measure from the technical level of database SQL statement fine control, and helps users to deal with data security threats from the inside and the outside by combining security access control rules independent of a database.
7. The data classification-based ranking screening process system of claim 1 wherein: the eagle eye engine adopts a machine learning algorithm to solve the safety problem by a mathematical method, improves the processing capacity of massive samples, and kills all mainstream viruses.
8. The data classification-based ranking screening process system of claim 1 wherein: the data classification module comprises a text data unit, a graphic data unit and an audio data unit, wherein the text data unit, the graphic data unit and the audio data unit are respectively electrically connected with the control unit and the data classification module, the text data unit is used for classifying received digital data, the graphic data unit is used for classifying the received graphic data, and the audio data unit is used for classifying the received audio data.
9. The data classification ranking-based screening process system of claim 8, wherein: the data grading module comprises a common data unit, an uncommon data unit and a common data unit, and the text data unit, the graphic data unit and the audio data unit correspond to a group of common data unit, an uncommon data unit and a common data unit.
10. The data classification-based ranking screening process system of claim 1 wherein: the data storage module comprises a main memory and an auxiliary memory, wherein the main memory and the auxiliary memory are both set to be ROM chips and are electrically connected with the data classification module.
CN202210951646.2A 2022-08-09 2022-08-09 Screening processing system based on data classification and classification Pending CN115208690A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202210951646.2A CN115208690A (en) 2022-08-09 2022-08-09 Screening processing system based on data classification and classification

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202210951646.2A CN115208690A (en) 2022-08-09 2022-08-09 Screening processing system based on data classification and classification

Publications (1)

Publication Number Publication Date
CN115208690A true CN115208690A (en) 2022-10-18

Family

ID=83586433

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202210951646.2A Pending CN115208690A (en) 2022-08-09 2022-08-09 Screening processing system based on data classification and classification

Country Status (1)

Country Link
CN (1) CN115208690A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115834633A (en) * 2022-11-30 2023-03-21 太原海关技术中心 A multi-laboratory networking system based on Internet big data
CN116665909A (en) * 2023-04-11 2023-08-29 北京宝通利达科技有限公司 A healthcare information processing system based on big data

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030145228A1 (en) * 2002-01-31 2003-07-31 Janne Suuronen System and method of providing virus protection at a gateway
CN101729259A (en) * 2008-10-14 2010-06-09 公安部第三研究所 Highly-safe data checking method for data switching system
US20130018945A1 (en) * 2011-04-11 2013-01-17 Vlad Vendrow User interface for accessing messages
CN204669399U (en) * 2015-04-23 2015-09-23 广州万方计算机科技有限公司 Based on internet worm and the threat monitoring system of Hadoop framework
CN107943661A (en) * 2017-12-12 2018-04-20 温州市联科科技有限公司 A kind of data storage management system
CN110457905A (en) * 2019-08-12 2019-11-15 腾讯云计算(北京)有限责任公司 Sample virus detection method, device, computer equipment and storage medium
CN112149170A (en) * 2020-10-12 2020-12-29 上海中尖实业(集团)有限公司 A digital big data security processing system
CN113918947A (en) * 2021-10-28 2022-01-11 深圳供电局有限公司 Electric power monitoring system
CN114546957A (en) * 2022-02-24 2022-05-27 新花漾信息技术(深圳)有限公司 Intelligent centralized data processing service platform

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030145228A1 (en) * 2002-01-31 2003-07-31 Janne Suuronen System and method of providing virus protection at a gateway
CN101729259A (en) * 2008-10-14 2010-06-09 公安部第三研究所 Highly-safe data checking method for data switching system
US20130018945A1 (en) * 2011-04-11 2013-01-17 Vlad Vendrow User interface for accessing messages
CN204669399U (en) * 2015-04-23 2015-09-23 广州万方计算机科技有限公司 Based on internet worm and the threat monitoring system of Hadoop framework
CN107943661A (en) * 2017-12-12 2018-04-20 温州市联科科技有限公司 A kind of data storage management system
CN110457905A (en) * 2019-08-12 2019-11-15 腾讯云计算(北京)有限责任公司 Sample virus detection method, device, computer equipment and storage medium
CN112149170A (en) * 2020-10-12 2020-12-29 上海中尖实业(集团)有限公司 A digital big data security processing system
CN113918947A (en) * 2021-10-28 2022-01-11 深圳供电局有限公司 Electric power monitoring system
CN114546957A (en) * 2022-02-24 2022-05-27 新花漾信息技术(深圳)有限公司 Intelligent centralized data processing service platform

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115834633A (en) * 2022-11-30 2023-03-21 太原海关技术中心 A multi-laboratory networking system based on Internet big data
CN116665909A (en) * 2023-04-11 2023-08-29 北京宝通利达科技有限公司 A healthcare information processing system based on big data
CN116665909B (en) * 2023-04-11 2024-05-24 柏瑞康(深圳)健康管理有限公司 A health information processing system based on big data

Similar Documents

Publication Publication Date Title
CN114465739B (en) Abnormal identification method and system, storage medium and electronic device
He et al. Software-defined-networking-enabled traffic anomaly detection and mitigation
US6968377B1 (en) Method and system for mapping a network for system security
US9438616B2 (en) Network asset information management
US6816973B1 (en) Method and system for adaptive network security using intelligent packet analysis
US7941855B2 (en) Computationally intelligent agents for distributed intrusion detection system and method of practicing same
CN111277587A (en) Malicious encrypted traffic detection method and system based on behavior analysis
CN111526121B (en) Intrusion prevention method and device, electronic equipment and computer readable medium
US8209759B2 (en) Security incident manager
EP3143547A1 (en) System and method for high speed threat intelligence management using unsupervised machine learning and prioritization algorithms
US20200195672A1 (en) Analyzing user behavior patterns to detect compromised nodes in an enterprise network
KR20140027616A (en) Apparatus and method for detecting http botnet based on the density of web transaction
CN103124226A (en) Household broadband net-system play monitoring system and method
CN106961428A (en) Centralized intrusion detection system based on private cloud platform
CN115208690A (en) Screening processing system based on data classification and classification
Sathya et al. Discriminant analysis based feature selection in kdd intrusion dataset
CN118784266A (en) An intelligent abnormal traffic blocking system based on machine learning algorithm and real-time traffic monitoring
Brahmi et al. Towards a multiagent-based distributed intrusion detection system using data mining approaches
KR20020072618A (en) Network based intrusion detection system
CN116389135A (en) A Network Security Monitoring System for Computer Communication
CN112383573B (en) Security intrusion playback equipment based on multiple attack stages
Sun et al. IoT‐IE: An Information‐Entropy‐Based Approach to Traffic Anomaly Detection in Internet of Things
EP4274160B1 (en) Machine learning based malware detection
CN113591072A (en) Attack event processing method, device, equipment and storage medium
CN119449433A (en) POE-driven multi-dimensional security monitoring and protection system for IoT devices

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20221018